You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android中调用Upstox授权API报错UDAPI100016,重定向配置存疑

Upstox API Android授权登录UDAPI100016重定向问题

我正在尝试使用Upstox API实现授权登录,参考其官方认证文档。编写了仅包含登录按钮及其监听器的MainActivity代码,但点击登录按钮时应用抛出UDAPI100016错误,该错误由重定向问题导致。我已在Web应用中解决此错误,但Android端仍出现该问题,想确认我的重定向配置是否正确。

我的MainActivity代码

package com.apps.upstoxtrade;

import androidx.appcompat.app.AppCompatActivity;

import android.net.Uri;
import android.os.Bundle;
import android.view.View;
import android.webkit.WebResourceRequest;
import android.webkit.WebView;
import android.webkit.WebViewClient;
import android.widget.Button;
import android.widget.Toast;

public class MainActivity extends AppCompatActivity {
    private static String AUTH_URL = "https://api-v2.upstox.com/login/authorization/dialog";
    private static final String RESPONSE_TYPE = "code";
    private static final String CLIENT_ID = "";
    private static final String REDIRECT_URI = "http://localhost:3000/redirect";


    @Override
    protected void onCreate(Bundle savedInstanceState) {
        super.onCreate(savedInstanceState);
        setContentView(R.layout.activity_main);
        Button loginButton = findViewById(R.id.login);
        loginButton.setOnClickListener(new View.OnClickListener() {
            @Override
            public void onClick(View v) {
                // Call the login functionality
                performLogin();
            }
        });
    }

    private void performLogin() {
        WebView webView = findViewById(R.id.webView);
        webView.getSettings().setJavaScriptEnabled(true);

        // Handle URL loading within the WebView itself
        webView.setWebViewClient(new WebViewClient() {
            @Override
            public boolean shouldOverrideUrlLoading(WebView view, WebResourceRequest request) {
                String url = request.getUrl().toString();
                // Check if the URL contains the authorization callback URL
                if (url.startsWith(AUTH_URL)) {
                    // Extract the code parameter from the URL
                    Uri uri = Uri.parse(url);
                    String code = uri.getQueryParameter("code");

                    // Use the code to get the access token
                    getAccessToken(code);

                    // Return true to indicate that the URL has been handled
                    return true;
                }
                return false;
            }
        });
        AUTH_URL = AUTH_URL+"?response_type="+RESPONSE_TYPE+"&client_id="+CLIENT_ID
                +"&redirect_uri="+REDIRECT_URI;

        webView.loadUrl(AUTH_URL);
    }

    private void getAccessToken(String code) {
        // You can use any networking library of your choice to make an HTTP request to fetch the access token.
        // Here, I'm using a simple synchronous HTTP request for demonstration purposes.

        // Replace this with the actual HTTP request code using your preferred networking library.
        String accessToken = fetchAccessToken(code);

        // Handle the access token as needed (e.g., store it, use it for further API requests, etc.).
        if (accessToken != null) {
            // Access token obtained, do something with it
            Toast.makeText(this,accessToken,Toast.LENGTH_LONG);
        } else {
            // Access token retrieval failed
        }
    }

    // Replace this method with your actual HTTP request code to fetch the access token
    private String fetchAccessToken(String code) {
        // Replace this with the actual code to fetch the access token using the "code" parameter.
        // You can use libraries like Retrofit, OkHttp, etc., to make the HTTP request.
        // For this example, I'm simply returning a hardcoded access token for demonstration purposes.

        // Example response: {"access_token":"your_access_token","expires_in":3600,"scope":"read"}
        return "your_access_token";
    }
}

错误截图

UDAPI100016错误截图


问题分析与解决方案

1. 重定向URI配置问题

你当前使用的http://localhost:3000/redirect是Web应用的重定向地址,并不适配Android场景:

  • Upstox API会验证请求中的重定向URI与开发者后台配置的完全一致,若后台仅配置了Web端地址,Android端使用相同地址会触发验证失败。
  • 推荐为Android应用配置自定义Scheme(如upstoxtrade://callback),这种方式更适合移动端跳转,避免localhost的兼容性问题。

2. WebView拦截逻辑错误

当前shouldOverrideUrlLoading方法判断的是URL是否以授权地址AUTH_URL开头,但登录成功后重定向的是你设置的REDIRECT_URI,所以拦截逻辑完全错误。修正代码如下:

@Override
public boolean shouldOverrideUrlLoading(WebView view, WebResourceRequest request) {
    String url = request.getUrl().toString();
    // 拦截重定向回调地址,而非授权地址
    if (url.startsWith(REDIRECT_URI)) {
        Uri uri = Uri.parse(url);
        String code = uri.getQueryParameter("code");
        if (code != null) {
            getAccessToken(code);
            return true;
        }
    }
    return false;
}

3. AUTH_URL重复拼接问题

你在performLogin方法中直接修改静态变量AUTH_URL,导致第二次点击登录按钮时,URL会重复拼接参数,引发请求错误。应改为临时拼接:

// 不要修改静态AUTH_URL,每次请求临时拼接参数
String loginUrl = AUTH_URL + "?response_type=" + RESPONSE_TYPE + "&client_id=" + CLIENT_ID + "&redirect_uri=" + REDIRECT_URI;
webView.loadUrl(loginUrl);

4. 自定义Scheme的Manifest配置

如果使用自定义Scheme作为重定向URI,需要在AndroidManifest.xml中为MainActivity添加intent-filter,确保应用能捕获该Scheme的跳转:

<activity android:name=".MainActivity">
    <intent-filter>
        <action android:name="android.intent.action.VIEW" />
        <category android:name="android.intent.category.DEFAULT" />
        <category android:name="android.intent.category.BROWSABLE" />
        <!-- scheme需与REDIRECT_URI中的一致,例如upstoxtrade -->
        <data android:scheme="upstoxtrade" />
    </intent-filter>
</activity>

最后,确保Upstox开发者后台中,你的Android应用条目下配置的重定向URI与代码中使用的完全一致,包括Scheme或域名路径。

内容的提问来源于stack exchange,提问作者Shadab

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 13:46:12